OpenAI employee ChatGPT/Codex account takeover via SSO trust boundary: agent blast radius
- Published
- 2026-09-22
- Type
- News
- Organization
- OpenAI
- Source
- HacktronAI / S1r1u5_
Why it matters
Researcher claim — Hacktron AI (Harsh Jaiswal, Mohan Pedhapati, Rahul Maini; public thread by @S1r1u5_) says that on 2026-07-25 they chained a community-forum foothold with an OpenAI SSO/token-permission flaw, taking over ChatGPT/Codex accounts of some OpenAI employees and other users who had signed into community.openai.com, and that connected connectors (email, Slack, GitHub, etc.) expanded the blast radius; they say they proved access by having an affected employee Codex open a harmless PR in OpenAI’s internal monorepo without reading sensitive code, reported via Bugcrowd, and that OpenAI confirmed a fix about 14 hours after the initial submission and later paid a $6,500 bounty for the OpenAI-side finding (Discourse-side image-processing issues reported separately). Media cross-check — SecurityWeek quotes OpenAI: it thanked the researchers, narrowed permissions on Community sign-in tokens, and revoked affected tokens and sessions; OpenAI also told SecurityWeek the image-processing bug lived in third-party Discourse while the account-takeover path was a separate OpenAI-side issue, that its review saw limited private-repo metadata/commit reads plus the researcher PR to a README, and that Hacktron did not verify actual employee Slack message access. A NY Post piece (2026-09-19) arguing labs “oversold” separate July evaluation-escape incidents for regulatory advantage is a different storyline and remains anonymous-insider media pending independent corroboration. Independent conclusion — high eval scores are not production safety. The dangerous surface of agents comes mainly from tool and identity binding: session hijack equals takeover of the proxy identity. The bottleneck on the path to stronger agents is not only reasoning, but least privilege, session isolation, and MCP/plugin boundaries; once agents attach to IDE/SSO/collaboration stacks, capability surface and incident radius grow together—this is a real AGI-path constraint, not a security sideshow.
Related developments
Aggregated by AGI Pulse. Titles and links only; no full text is republished.